Description
OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply: true despite approvalPolicy: pending configuration. Attackers can exploit this by reaching the affected apply path to apply workshop changes before the expected approval step, potentially modifying configurations without proper authorization.
Published: 2026-06-11
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises in OpenClaw versions prior to 2026.5.6 and allows an attacker who can reach the Skill Workshop apply endpoint to set the apply flag to true even though the approvalPolicy is configured as pending. This bypass enables the attacker to apply workshop changes without proper authorization, thereby potentially altering system configurations or workflows that should have required an explicit approval step. The weakness is classified as CWE‑863, indicating an authorization bypass. Based on the description, it is inferred that an attacker must be able to reach the Skill Workshop apply endpoint to exploit this flaw.

Affected Systems

The affected product is OpenClaw, specifically the component known as OpenClaw. All installations running a version earlier than 2026.5.6 are considered vulnerable; no narrower version range is specified in the available data.

Risk and Exploitability

The CVSS score of 6.0 identifies this issue as a moderate severity vulnerability. No EPSS score is available, so the exact likelihood of exploitation is unclear; however, the attack path requires access to the affected apply path, suggesting that attackers would need at least application-level access. The vulnerability is not listed in CISA KEV, indicating it may not have been exploited in the wild yet. Based on the description, it is inferred that if the apply path is exposed to untrusted users, the risk escalates, potentially enabling unauthorized changes that can compromise system integrity. Based on the description, it is inferred that attackers would need application-level access to the affected apply path, and that exposure of the apply endpoint to untrusted parties would increase risk.

Generated by OpenCVE AI on June 11, 2026 at 22:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenClaw to version 2026.5.6 or later to contain the authorization check that enforces the approval policy.
  • Restrict access to the Skill Workshop apply endpoint so that only trusted administrators can invoke it, thereby limiting the potential for unauthorized use.
  • Enforce additional monitoring and logging around the apply action to detect any unexpected use of apply:true that bypasses the approval workflow.

Generated by OpenCVE AI on June 11, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 11 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows agent tool calls to set apply: true despite approvalPolicy: pending configuration. Attackers can exploit this by reaching the affected apply path to apply workshop changes before the expected approval step, potentially modifying configurations without proper authorization.
Title OpenClaw < 2026.5.6 - Approval Policy Bypass in Skill Workshop Apply Flow
First Time appeared Openclaw
Openclaw openclaw
Weaknesses CWE-863
CPEs cpe:2.3:a:openclaw:openclaw:*:*:*:*:*:node.js:*:*
Vendors & Products Openclaw
Openclaw openclaw
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Openclaw Openclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-06-11T20:06:14.018Z

Reserved: 2026-06-10T21:14:38.834Z

Link: CVE-2026-53808

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-11T21:16:22.717

Modified: 2026-06-11T21:16:22.717

Link: CVE-2026-53808

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-11T22:45:05Z

Weaknesses